CVE-2026-57123Critical· 9.8▾ MidnightPraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonaiagents < 1.6.59Patched in:
praisonaiagents 1.6.59Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57112High· 8.3PraisonAI is a multi-agent teams system
CVE-2026-57120Medium· 6.5PraisonAI is a multi-agent teams system
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57125Critical· 9.8PraisonAI is a multi-agent teams system
GHSA-x227-pf99-vffgCritical· 9.8PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
CVE-2026-57122High· 8.6PraisonAI is a multi-agent teams system